V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2014-0160
DEB
High KEVConfirmedExploit available

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows re…

CVSS
7.5
High
EPSS
0.94
p99
Published
2014-01-01
Updated
2022-05-04
Description

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

Tags · CWE
KEVRCEPre-auth
CWE-125
CWE-130
CAPEC-47
CAPEC-540
Affected products
Debian_linux
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Timeline
2014-01-01
Published
2022-05-04
Added to KEV
2022-05-04
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.945 · p99
Known exploited (KEV)
Yes
Known exploits — Сканер-ВС
CVE-2014-0160
cisa · https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Enterprise
32745
exploitdb · https://www.exploit-db.com/exploits/32745
Enterprise
32764
exploitdb · https://www.exploit-db.com/exploits/32764
Enterprise
32791
exploitdb · https://www.exploit-db.com/exploits/32791
Enterprise
32998
exploitdb · https://www.exploit-db.com/exploits/32998
Enterprise
Affected software
ProductVendorStatus
opensslExploited
opensslExploited
opensslExploited
opensslExploited
rhev-hypervisor6Exploited
rhev-hypervisor6Exploited
spice-client-msiExploited
application_processing_engine_firmware*Exploited
cp_1543-1_firmware*Exploited
debian_linux*Exploited
elan-8.2*Exploited
enterprise_linux_desktop*Exploited
enterprise_linux_server*Exploited
enterprise_linux_server_aus*Exploited
enterprise_linux_server_eus*Exploited
enterprise_linux_server_tus*Exploited
enterprise_linux_workstation*Exploited
fedora*Exploited
filezilla_server*Exploited
gluster_storage*Exploited
Source databases
DEB
CVE
RED
Related vulnerabilities